
 dlatego prosze o sprawdzenie mojego loga bo byc moze mam jakiegos wirusa...z gory dzieki za pomoc.pozdro!
 dlatego prosze o sprawdzenie mojego loga bo byc moze mam jakiegos wirusa...z gory dzieki za pomoc.pozdro!  
- Kod: Zaznacz wszystko
- "Silent Runners.vbs", revision R50, http://www.silentrunners.org/
 Operating System: Windows XP SP2
 Output limited to non-default values, except where indicated by "{++}"
 Startup items buried in registry:
 ---------------------------------
 HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
 "CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
 "MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]
 "swg" = "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" ["Google Inc."]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
 "SynTPEnh" = "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" ["Synaptics, Inc."]
 "Skrót do strony właściwości High Definition Audio" = "HDAShCut.exe" ["Windows (R) Server 2003 DDK provider"]
 "TPHOTKEY" = "C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe" [null data]
 "TPWAUDAP" = "C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe" [null data]
 "PMHandler" = "C:\WINDOWS\system32\PMHandler.exe" ["Lenovo"]
 "AGRSMMSG" = "AGRSMMSG.exe" ["Agere Systems"]
 "Broadcom Wireless Manager UI" = "C:\WINDOWS\system32\WLTRAY.exe" ["Broadcom Corporation"]
 "igfxtray" = "C:\WINDOWS\system32\igfxtray.exe" ["Intel Corporation"]
 "igfxhkcmd" = "C:\WINDOWS\system32\hkcmd.exe" ["Intel Corporation"]
 "igfxpers" = "C:\WINDOWS\system32\igfxpers.exe" ["Intel Corporation"]
 "suScheduler" = "C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER" [null data]
 "ISUSPM Startup" = "c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup" ["InstallShield Software Corporation"]
 "ISUSScheduler" = ""c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start" ["InstallShield Software Corporation"]
 "OmniPass" = "C:\Program Files\Softex\OmniPass\scureapp.exe" [null data]
 "AMSG" = "C:\PROGRA~1\THINKV~1\AMSG\amsg.exe" ["LENOVO"]
 "LPManager" = "C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe" ["Lenovo Group Limited"]
 "ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"]
 "URLLSTCK.exe" = "C:\Program Files\Norton Internet Security\UrlLstCk.exe" ["Symantec Corporation"]
 "cssauthe" = ""C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauthe.exe" silent" ["Lenovo Group Limited"]
 "Picasa Media Detector" = "C:\Program Files\Picasa2\PicasaMediaDetector.exe" ["Google Inc."]
 "Google Desktop Search" = ""C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup" [null data]
 "ACTray" = "C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" ["Lenovo"]
 "ACWLIcon" = "C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" ["Lenovo"]
 "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
 "WinampAgent" = "C:\Program Files\Winamp\winampa.exe" [null data]
 "SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"" ["Sun Microsystems, Inc."]
 "QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
 {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "AcroIEHlprObj Class"
 \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
 {22BF413B-C6D2-4d91-82A9-A0F997BA588C}\(Default) = "Skype add-on (mastermind)"
 -> {HKLM...CLSID} = "Skype add-on (mastermind)"
 \InProcServer32\(Default) = "C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL" ["Skype Technologies S.A."]
 {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "SSVHelper Class"
 \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll" ["Sun Microsystems, Inc."]
 {9ECB9560-04F9-4bbc-943D-298DDF1699E1}\(Default) = "Norton Internet Security"
 -> {HKLM...CLSID} = "CNisExtBho Class"
 \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
 {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "Google Toolbar Helper"
 \InProcServer32\(Default) = "c:\program files\google\googletoolbar3.dll" ["Google Inc."]
 {BDF3E430-B101-42AD-A544-FADC6B084872}\(Default) = "NAV Helper"
 -> {HKLM...CLSID} = "CNavExtBho Class"
 \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
 {C08DF07A-3E49-4E25-9AB0-D3882835F153}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "QUICKfind BHO Object"
 \InProcServer32\(Default) = "C:\PROGRA~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll" [null data]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
 "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
 -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
 \InProcServer32\(Default) = "deskpan.dll" [file not found]
 "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
 -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
 "{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\Program Files\Synaptics\SynTP\SynTPCpl.dll" ["Synaptics, Inc."]
 "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
 -> {HKLM...CLSID} = "Portable Media Devices Menu"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
 "{6af09ec9-b429-11d4-a1fb-0090960218cb}" = "My Bluetooth Places"
 -> {HKLM...CLSID} = "Moje miejsca interfejsu Bluetooth"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\btneighborhood.dll" ["Broadcom Corporation."]
 "{D0CE97A0-415B-42E9-B251-34393AF2D5F6}" = "OmniPass Shell Extension"
 -> {HKLM...CLSID} = "Softex OmniPass Encrypted File"
 \InProcServer32\(Default) = "C:\Program Files\Softex\OmniPass\opfolderext.dll" ["Softex Inc."]
 "{D5B1944E-DB4E-482E-B3F1-DB05827F0978}" = "OmniPass ShellNameSpace Extension"
 -> {HKLM...CLSID} = "Softex OmniPass Encrypted Folder"
 \InProcServer32\(Default) = "C:\Program Files\Softex\OmniPass\opfolderext.dll" ["Softex Inc."]
 "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
 -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
 \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\
 <<!>> "AppInit_DLLs" = "C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL" [null data]
 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
 <<!>> ACNotify\DLLName = "ACNotify.dll" [file not found]
 <<!>> igfxcui\DLLName = "igfxdev.dll" ["Intel Corporation"]
 <<!>> OPXPGina\DLLName = "C:\Program Files\Softex\OmniPass\opxpgina.dll" [null data]
 <<!>> tphotkey\DLLName = "tphklock.dll" [null data]
 HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
 {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
 -> {HKLM...CLSID} = "PDF Shell Extension"
 \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]
 HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
 OPShellExt\(Default) = "{D0CE97A0-415B-42E9-B251-34393AF2D5F6}"
 -> {HKLM...CLSID} = "Softex OmniPass Encrypted File"
 \InProcServer32\(Default) = "C:\Program Files\Softex\OmniPass\opfolderext.dll" ["Softex Inc."]
 Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
 -> {HKLM...CLSID} = "IEContextMenu Class"
 \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
 HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
 OPShellExt\(Default) = "{D0CE97A0-415B-42E9-B251-34393AF2D5F6}"
 -> {HKLM...CLSID} = "Softex OmniPass Encrypted File"
 \InProcServer32\(Default) = "C:\Program Files\Softex\OmniPass\opfolderext.dll" ["Softex Inc."]
 HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
 Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
 -> {HKLM...CLSID} = "IEContextMenu Class"
 \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
 Group Policies {policy setting}:
 --------------------------------
 Note: detected settings may not have any effect.
 HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\
 "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
 {Shutdown: Allow system to be shut down without having to log on}
 "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
 {Devices: Allow undock without having to log on}
 Active Desktop and Wallpaper:
 -----------------------------
 Active Desktop may be disabled at this entry:
 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
 Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
 HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
 "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"
 Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
 HKCU\Control Panel\Desktop\
 "Wallpaper" = "C:\Documents and Settings\EVELA\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"
 Enabled Screen Saver:
 ---------------------
 HKCU\Control Panel\Desktop\
 "SCRNSAVE.EXE" = "C:\WINDOWS\system32\sstext3d.scr" [MS]
 Startup items in "EVELA" & "All Users" startup folders:
 -------------------------------------------------------
 C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
 "Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]
 "BTTray" -> shortcut to: "C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe" ["Broadcom Corporation."]
 "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS]
 Enabled Scheduled Tasks:
 ------------------------
 "AppleSoftwareUpdate" -> launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -Task" ["Apple Computer, Inc."]
 "Norton AntiVirus - Skanuj komputer - EVELA" -> launches: "C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe /task:"C:\Documents and Settings\All Users\Dane aplikacji\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" ["Symantec Corporation"]
 Winsock2 Service Provider DLLs:
 -------------------------------
 Namespace Service Providers
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 Transport Service Providers
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
 %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
 Toolbars, Explorer Bars, Extensions:
 ------------------------------------
 Toolbars
 HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
 "{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"
 -> {HKLM...CLSID} = "Norton Internet Security"
 \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
 "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
 -> {HKLM...CLSID} = "&Google"
 \InProcServer32\(Default) = "c:\program files\google\googletoolbar3.dll" ["Google Inc."]
 "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
 -> {HKLM...CLSID} = "Norton AntiVirus"
 \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
 HKLM\Software\Microsoft\Internet Explorer\Toolbar\
 "{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" = "Norton Internet Security"
 -> {HKLM...CLSID} = "Norton Internet Security"
 \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
 "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus"
 -> {HKLM...CLSID} = "Norton AntiVirus"
 \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
 "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
 -> {HKLM...CLSID} = "&Google"
 \InProcServer32\(Default) = "c:\program files\google\googletoolbar3.dll" ["Google Inc."]
 Extensions (Tools menu items, main toolbar menu buttons)
 HKLM\Software\Microsoft\Internet Explorer\Extensions\
 {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
 "MenuText" = "IBM Java Console"
 "CLSIDExtension" = "{08B0E5C0-4FCB-11CF-AAA5-00401C608501}"
 {77BF5300-1474-4EC7-9980-D32B190E9B07}\
 "ButtonText" = "Skype"
 "CLSIDExtension" = "{77BF5300-1474-4EC7-9980-D32B190E9B07}"
 -> {HKLM...CLSID} = "Skype add-on (button)"
 \InProcServer32\(Default) = "C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL" ["Skype Technologies S.A."]
 {FB5F1910-F110-11D2-BB9E-00C04F795683}\
 "ButtonText" = "Messenger"
 "MenuText" = "Windows Messenger"
 "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]
 Miscellaneous IE Hijack Points
 ------------------------------
 C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")
 Added lines (compared with English-language version):
 [Strings]: START_PAGE_URL=http://www.lenovo.com/us/en/
 Missing lines (compared with English-language version):
 [Strings]: 1 line
 Running Services (Display Name, Service Name, Path {Service DLL}):
 ------------------------------------------------------------------
 Ac Profile Manager Service, AcPrfMgrSvc, "C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe" [null data]
 Access Connections Main Service, AcSvc, "C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe" ["Lenovo"]
 Bluetooth Service, btwdins, "C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe" ["Broadcom Corporation."]
 Creative Service for CDROM Access, Creative Service for CDROM Access, "C:\WINDOWS\system32\CTsvcCDA.EXE" ["Creative Technology Ltd"]
 Harmonogram automatycznej usługi LiveUpdate, Harmonogram automatycznej usługi LiveUpdate, ""C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"" ["Symantec Corporation"]
 ISSvc, ISSVC, ""C:\Program Files\Norton Internet Security\ISSVC.exe"" ["Symantec Corporation"]
 PMSveH, PMSveH, "C:\WINDOWS\system32\PMSveH.exe" ["Lenovo"]
 Softex OmniPass Service, omniserv, "C:\Program Files\Softex\OmniPass\Omniserv.exe" ["Softex Inc."]
 Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"]
 Symantec Network Drivers Service, SNDSrvc, ""C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"" ["Symantec Corporation"]
 Symantec Network Proxy, ccProxy, ""C:\Program Files\Common Files\Symantec Shared\ccProxy.exe"" ["Symantec Corporation"]
 Symantec Settings Manager, ccSetMgr, ""C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"" ["Symantec Corporation"]
 Symantec SPBBCSvc, SPBBCSvc, ""C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"" ["Symantec Corporation"]
 ThinkVantage System Update, UCLauncherService, "C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe" [null data]
 TVT Backup Service, TVT Backup Service, ""C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe"" [empty string]
 TVT Scheduler, TVT Scheduler, ""C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe"" [empty string]
 Usługa Auto-Protect programu Norton AntiVirus, navapsvc, ""C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"" ["Symantec Corporation"]
 Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]
 Print Monitors:
 ---------------
 HKLM\System\CurrentControlSet\Control\Print\Monitors\
 Port drukarki interfejsu Bluetooth\Driver = "bthcrp.dll" ["Broadcom Corporation."]
 ----------
 <<!>>: Suspicious data at a malware launch point.
 + This report excludes default entries except where indicated.
 + To see *everywhere* the script checks and *everything* it finds,
 launch it from a command prompt or a shortcut with the -all parameter.
 + To search all directories of local fixed drives for DESKTOP.INI
 DLL launch points, use the -supp parameter or answer "No" at the
 first message box and "Yes" at the second message box.
 ---------- (total run time: 95 seconds, including 18 seconds for message boxes)

 
	

 
	
